Governing AI: What a Japanese castle’s layered design teaches us

Chat GPT was first released in 2022. It worked as a single assistant that provided answers to anything you asked. Fast forward to 2026, AI has exploded exponentially. The new era has created multiple agents that are capable of creating their own autonomy. These new bots read data, make judgement and take real action without human interference. And these numbers will only grow as times go on.

Although it’s a projection, a new Gartner report stated that large enterprises running fewer than 15 agents in 2025 could be running the order of 150,000 by 2028. The future predicts it will not stop just there. And that’s a scary prospect. Not only for you but your companies and future business. Because multiplying technologies doesn’t necessarily mean that they will be successful.

This leads us back to what we are discussing in this article. How will you find a good product in this sea of technology? How can you actually govern Ai?

Why is it necessary to govern AI?

Most of the early 2026 surveys have found that while roughly nine in ten organizations already use AI agents in some form, only about one in ten have a clear strategy for managing those agents’ identities. Close to nine in ten reported a confirmed or suspected agent-related security incident in the prior year. And only about a fifth treat their agents as distinct identities at all (most still hand them the same human credentials or shared keys they already had on hand). Access control simply hasn’t been separated between people and agents.

This is normal in the story of fast adoptions. One team will connect agents to their internal data to save time and chain tasks together. Each step is small and reasonable. The accumulation is neither.

What’s making these agentic Ais different from earlier automations is that they acquire permissions as they run, call external tools, and act across many systems. So, the blast radius of a single overreach – or one leaked credential – is far wider than it used to be. Access control and governance simply haven’t kept pace with how fast the agents multiply.

Why There’s No “Buy” Button For This

Enterprises get another hurdle of solving this problem. What do you buy to fix this?

Last month in San Francisco, the industry’s largest data-platform conference made AI-agent governance its central theme. This model had the ability to fine-grain permission control, audit logs that retained every action, and to be able to halt an agent when something goes wrong.

These are powerful controls, but with a specific edge that takes out others. The narrator itself said, “it’s not the model itself that has the advantage, but how you place the data and context into it.” A competitor can go and replicate the same model, but it will be the design around it that will be visible in your ROI.

Governance has always been a design problem first and a product problem second. So how do you draw a perfect structure that compliments your data and something that fits well?

Thinking In Layers – The Castle’s “Nawabari”

The Japanese people are known for their infrastructure. From adapting to earthquake resistant houses to making an unbreachable castle back in the days, they are strategic and methodical.

Let’s take a look at this perfect example of Inyuma castle.

A great castle isn’t defended by one tall wall. Its strength is in layers an outer moat, then a series of baileys nested one inside the next, and finally the keep at the center. Each enclosure has its own gate, and each gate re-checks what the last one already verified. The architects never assumed that every defence would hold but more so that they prepared for every fatality and arranged the layers so that no failure is fatal.  

This method of building castles was called Nawabari. A master layout that artists used to have geography in their favor. They methodically built the castle so that every bailey, moat and forest wall could play a part in protecting the main castle. And that is also how you would want your AI governance to shape. Because with precision and strategy, comes returns and efficiency. In a shaped AI governance based on Nawabari, you can distinguish them as:

  • Boundary (the moat): The part where the model and data will sit. Just like the messenger entering the first security check, the decisions will take place there.
  • Identity & access (the main gate) The system decides who will enter. each agent gets its own identity, not a borrowed human credential, and the privilege it’s granted starts at the minimum.
  • Zoned access (the baileys) Not all ground inside the walls is equal; data is partitioned by sensitivity. An agent admitted to an outer bailey has no business in the inner one. Access is scoped to purpose and re-checked at each layer, not granted once at the door.
  • Most-critical zone (the keep) The most sensitive data and the highest-impact actions sit innermost, reached only after every gate has held and the most consequential actions require more than one approval.
  • Continuous oversight (the watchtower) The vantage point that surveys the whole at once.
  • Containment (the drawbridge) A well-built castle can isolate itself; when an agent drifts, you can revoke its access and contain the damage at once.

The layers aren’t redundancy. They are the design. One guarded gate is a door. Five gates, each checking again, is a castle.

How Automated Governance works as a Watchtower

Castles had humans who could stand watch. This generation needs more agents because you can’t have a person posted at every gate. Especially in agent governance where practitioners believe that only manual review doesn’t solve the problem.

To put it plainly: the only thing that can watch AI agents at the speed they move is another AI. Governance at scale becomes an agent watching the agents from the tower,  keeping, literally, an AI on the AI. That isn’t the abandonment of human control. It’s the inspector’s discipline, encoded so it never sleeps.

The decisions worth making at the start

The nawabari idea carries one more practical implication: the decisions hardest to change later are the ones worth making consciously at the start.

For enterprises operating in Japan, two such decisions are worth setting early. One is where inference runs, and the other is how the system handles the Japanese language itself. Embedding various models to give AI agents understanding and evaluations that test their judgements are run in Japanese to build the operation closer to foundation stones and achieve maximum result.

In closing

“What will distinguish enterprises in the agentic era isn’t the number of agents or the model they chose. It’s whether governance was designed in layers from the start, and whether a tireless, automated watcher keeps an eye on those layers.”

A castle was never built to hide inside. It existed so the town below could trade and build and prosper, safely. Good defense wasn’t the opposite of growth; it was its precondition. The same holds here: design the layers and automate the watch, and you can let your agents do far more, far faster, with far less fear.

Governance isn’t a brake. It’s the ground you push off from.

kumar gaurav harsh
senior principal consultant

Related Success Stories